Apache CouchDB versions prior to version 0.11.0 are
vulnerable to timing attacks, also known as side-channel information leakage,
due to using simple break-on-inequality string comparisons when verifying hashes
and passwords.